ISNow – Enterprise Security

The following introduction was originally published in the BCS Information Security Now Magazine, Autumn 2006 issue (Volume 1, Issue 1), which was on the topic of Enterprise Security:

Enterprise security
The main topic of this issue has nothing to do with a star ship, but nonetheless is about a voyage of discovery into the new and unknown. As businesses become more interconnected and mobile, network boundaries erode, providing more ways for attackers to compromise them. Enterprises need to find new ways of understanding, and coping with, this brave new world.

Businesses are now often wholly reliant on electronic processing of information for their existence and financial well-being. It is more critical than ever for enterprises to take the necessary measures to ensure information remains private, accurate and available at the point of need.

This information is now distributed among known critical business systems, other systems, the (often mobile) workforce and third (and fourth) parties. Ensuring appropriate contractual, procedural and technical controls are in, and remain in, place is a skill that all enterprises need to master.

We face a growing and changing landscape of exposure to vulnerabilities which attackers are more eager than ever to exploit, often before there is a direct mitigation. Financial gain is a great motivator – maybe defenders should learn this lesson as well as the attackers.

The enterprise has to realize that the demilitarized zone (DMZ) has been occupied and the concept of a trusted network needs consigning to the history books. Every system must be able to defend itself from its neighbour, because it will often be impossible to identify friend or foe.

Innovate – don’t legislate
Over recent years, there has been an increase in legislation and regulation, both national and international, affecting businesses.The coverage has been broad and shows no sign of abating.Technology is no fix in itself and poorly drafted and misapplied rules do little to help, and often hinder.

As we see increased demands for data privacy, protection, interception, retention, breach notifications and computer misuse, some governments are working around their own rules to access or share information in a way that might be incompatible with legal and official procedures.

No one should have the moral or legal authority to both enforce the law and evade it.The spirit is equally, if not more, important than the letter of the law, and governments should remember this when requiring the rest of us to operate within it.

We should engage more in consultations and lobbying related to forthcoming legislation and regulations that may affect us. If bad ideas or drafting reach the statute book, unintended consequences may well impact on us in a way that damages our ability to be effective businesses, and countries.”

A PDF version of the magazine is available online at:

http://www.bcs.org/upload/pdf/isNOW_autumn2006.pdf